Short answer
Users must know they are talking to AI at the first interaction
Article 50 of the AI Act requires providers to design direct-interaction systems so people are informed that they are interacting with AI, unless that is obvious. The website owner must also check its own duties as deployer and data controller.
When and how to disclose an AI chatbot
The information must be clear, visible and accessible no later than the first interaction. A label such as “AI assistant” in the chat header and a short sentence before the input are stronger than a disclosure buried in general terms.
The duty concerns direct interaction with an AI system. It is not a general rule requiring every website built with AI to carry a label. Synthetic content, deepfakes and certain public-interest text follow other paragraphs and exceptions in Article 50.
The GDPR still applies behind the chat window
The Belgian DPA notes that free text makes it hard to predict all data people may send. Limit what is requested, warn against unnecessary sensitive information, define purposes, recipients and retention, and provide access and deletion paths.
- Before input: AI identity, message use, useful warning and link to detailed information.
- During: data minimisation, detection of obvious secrets, human escalation and no misleading promises.
- After: documented retention, rights, deletion, logs and supplier control.
The AI Act ceiling is not a small website’s invoice
Article 99 provides up to €15 million or 3% of worldwide annual turnover for certain breaches of operator duties, including Article 50. For SMEs and start-ups, the applicable maximum is the lower of those amounts. Nature, severity, duration, responsibility, cooperation and corrective action are assessed.
The figure matters only when the system, role and obligation are actually in scope. Presenting it as an automatic fine for every chatbot would be false.
What Hebora tests on the published chatbot
- First interaction. AI label, placement, readability, accessibility and mobile consistency.
- Flows. Messages, files, metadata, suppliers, region, logs and exposed keys.
- Risk journeys. Sensitive data, deletion request, hallucination, incident and human handover.
- Delivery. Captures, flow inventory, configured retention, technical corrections and questions for the DPO or lawyer.
Verified official sources
- EUR-Lex — European Artificial Intelligence Act, Articles 50 and 99
- EUR-Lex — Regulation (EU) 2026/1744, Digital Omnibus on AI
- European Commission — guidelines on AI Act transparency obligations
- FPS Economy — you use AI in your company
- Belgian Data Protection Authority — chatbots, innovation and data protection (official source in Dutch)
- EUR-Lex — General Data Protection Regulation (GDPR)
Sources checked on 15 August 2026.